Skip to content

← Back to blog

Frameworks · 7 min read · 2026-09-02

PMBOK Risk Management, Mapped to KinetiRisk

A walk through every PMBOK risk process, with the specific part of KinetiRisk that does the work: AI scoring, response strategies, weighted mitigation and residual forecasting.

If you were trained on the PMBOK Guide, you already have a mental model for managing risk: plan how you will do it, identify what could go wrong, analyse it, plan a response, carry that response out, and keep watching. The problem is rarely the method. It is that most tools make you run the method by hand while they store a list.

KinetiRisk was built the other way round. The processes in the PMBOK risk knowledge area are the product, not a set of parts you assemble yourself. This is not a PMBOK tutorial: it assumes you know the vocabulary and want to see how a tool maps onto it.


How KinetiRisk Maps to PMBOK Risk Management

KinetiRisk maps each of the six PMBOK risk processes to a specific part of the product. Plan risk management is project settings: scales, categories, roles and the escalation threshold. Identify risks is the register, CSV import and AI interdependency detection. Perform qualitative risk analysis is AI probability and impact scoring with human review. Plan risk responses is the response strategy field plus AI-drafted mitigation actions. Implement risk responses is the action tracker with owners, due dates and progress. Monitor risks is the live dashboard, review reminders and risk change history. The rest of this article takes them one at a time.

There is no separate quantitative analysis process: KinetiRisk stays with the qualitative probability times impact model that PMBOK, PRINCE2 and ISO 31000 all share, rather than Monte Carlo simulation or expected monetary value.


Plan Risk Management

PMBOK expects a risk management plan that sets out your scales, categories, roles and thresholds before anyone scores a risk. In KinetiRisk that lives in project settings rather than a separate document that goes stale.

Probability and impact scales
Each project defines what 1 to 5 means for probability and for impact, in its own words. The AI is calibrated against those definitions, and they show as tooltips wherever a score is set, so a 3 means the same thing to everyone on the project.
Risk breakdown structure
A two-level category tree per project. Categories and sub-categories are yours to name, and every risk is filed against a path so you can see where exposure concentrates.
Escalation threshold
A single number per project. When probability times impact reaches it, the risk escalates automatically. The default is 15 out of 25.
Roles
Project Manager, Viewer and Super Admin, scoped to project membership. People see and change only the projects they belong to.

Identify Risks

Getting risks into the register should be the easy part. KinetiRisk gives you three routes in.

Manual entry
A short form: title, description, owner. That is enough for the AI to work with.
CSV import
Bring an existing spreadsheet across in one go. Column mapping is automatic for the common headers, including risk type, response strategy, proximity and review date, and unmatched values import with a warning rather than failing the row.
AI interdependencies
During a full analysis the AI looks at the other open risks on the project and flags the ones this risk would genuinely make worse, with the causal chain spelled out.

Each risk carries the fields a PMBOK register expects: an identifier, a title, a description, an owner, a category path, a risk type of threat or opportunity, and a response strategy.


Perform Qualitative Risk Analysis

This is where consistency matters most, and where a blank spreadsheet cell does the most damage. KinetiRisk proposes a probability and an impact score from 1 to 5, each with a short plain-English explanation of how it got there. You can accept it, change it, or re-run it.

Scores land on a shaded 5 by 5 grid, so the shape of the project's exposure is visible at a glance. If you want the detail of how the bands and thresholds are set, we cover it in how probability times impact scoring actually works. Nothing is confirmed on the AI's say-so: every proposed score sits in a review state until a person signs it off, and any override is recorded against the original number.


Plan Risk Responses

For a threat, the AI drafts a set of mitigation actions, each with a suggested owner role and a weight showing how much of the risk reduction it is expected to carry. For an opportunity it drafts steps to capture the upside instead.

The response strategy field maps straight onto PMBOK's vocabulary. Threats take avoid, reduce, transfer, accept, or prepare a contingency. Opportunities take exploit, enhance, share, or reject. The AI recommends one during a full analysis and you can change it before approval.


Implement Risk Responses

Every action has an owner, a due date and a status that moves through pending, in progress, complete or cancelled. A My Actions view collects everything assigned to a person across all their projects, so the work does not depend on anyone re-reading the register.

As actions complete, progress is tracked against the residual score the AI forecast for the risk, so you can see how far the plan has actually moved the exposure rather than how many boxes are ticked. Weighted mitigation progress is on the Team plan.


Monitor Risks

PMBOK treats monitoring as continuous, and this is the part a static document cannot support. KinetiRisk keeps the register live.

Dashboard
A heatmap, an escalation feed and a reviews-due count, refreshed as risks change.
Review reminders
Set a review date on a risk or a cadence for the whole project. Overdue risks surface on the dashboard, and their owners get an email. This is on every plan, Free included.
Risk change history
Every change to a score, status, owner or note is timestamped against the person who made it. Also on every plan.
Portfolio view
Risks roll up from project to programme to portfolio without being re-entered. Portfolio risk clustering, which groups related risks across projects, is on the Team plan.
Board narrative
A written summary with a RAG status, generated from the register as it stands. Available from the Starter plan.

Where KinetiRisk Goes Further Than PMBOK

Three things sit slightly outside the guide as written.

  • AI-assisted scoring. It replaces the manual expert-judgement step while keeping a human accountable for the result through review and override.
  • Residual risk forecasting. It ties mitigation progress to an expected post-mitigation exposure. A traditional register records the residual score after the event; KinetiRisk forecasts it and tracks towards it.
  • Portfolio risk clustering. It does the cross-project systemic analysis that PMBOK describes in principle and leaves as a manual exercise.

The first of those is the one that raises questions, so we wrote separately about AI risk scoring and governance: what the AI decides, what stays with the reviewer, and how the record holds up afterwards.

KinetiRisk follows the PMBOK risk processes by default, on a free tier that never expires. Start free.

Start free See how it works

The Free plan gives you one project, 25 AI analyses a month, the full analysis including mitigation planning and reasoning, automatic escalation alerts, review reminders and the hierarchical category tree. No card, no time limit.

If you work in a PRINCE2 environment instead, the mapping is a little different: proximity, separate threat and opportunity registers, and escalation to programme all carry more weight. We cover that in how KinetiRisk supports PRINCE2 risk management.


Frequently Asked Questions

Does KinetiRisk follow the PMBOK Guide?

It follows the risk management processes in the PMBOK Guide: plan risk management, identify risks, perform qualitative analysis, plan responses, implement responses and monitor. Each one maps to a specific part of the product rather than a feature you configure. It does not implement the quantitative analysis process, which relies on Monte Carlo simulation and expected monetary value.

Where do PMBOK risk response strategies live in KinetiRisk?

On the risk itself, as a response strategy field. Threats take avoid, reduce, transfer, accept or prepare a contingency; opportunities take exploit, enhance, share or reject. The AI recommends one during a full analysis and you can override it before the risk is approved.

Can I import an existing PMBOK risk register?

Yes. Upload it as a CSV and KinetiRisk maps the common columns automatically, including probability, impact, category, response strategy, proximity and review date. Rows with values it does not recognise still import, with a warning, so nothing is lost silently.

Is the AI making risk decisions?

No. The AI proposes probability and impact scores with its reasoning, and drafts mitigation actions. A person reviews and confirms every score, and any change is recorded against the original. Escalation is separate again: it is an automatic rule that fires when probability times impact reaches the project threshold, with no AI involvement.

What does PMBOK risk management cost in KinetiRisk?

The core processes are on the Free plan: one project, 25 AI analyses a month, full analysis, automatic escalation, review reminders and risk change history, with no card required and no expiry. Residual risk forecasting starts on Starter at £5 a month; portfolio risk clustering and weighted mitigation progress are on Team at £25 a month for 10 seats.

PMBOK gives you a sound process. The gap has always been between knowing the process and doing it every week without a dedicated risk function. KinetiRisk closes that gap by making the process the default behaviour of the tool, so a project manager can work inside it from day one without ever opening the guide.

Start free →